External risk intelligence

SQL Injection in Online Fire Reporting System

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-40690

The vulnerability exists in an administrative endpoint of a web-based reporting system. While intended for management, such web-based administrative interfaces are frequently deployed with internet-facing access in small-scale or public-sector environments, making them plausibly reachable over the public internet.

SQL Injection

Phpgurukul Online Fire Reporting System

1.2

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in an online fire reporting system, potentially allowing unauthorized access to and manipulation of database information. This issue affects the administrative functions of the system, posing a risk to the integrity and confidentiality of reported data. The main concern is confirming the system's relevance and whether it is currently in use.

  • System vulnerability allows database access and changes.
  • Important for leaders to know if this system is used.
  • Confirm system relevance and data protection needs.

Attack Path

How an attacker could exploit the issue

An attacker can target the Online Fire Reporting System by sending specially crafted requests to the `/ofrs/admin/edit-team.php` endpoint. By manipulating the 'teamid' parameter, an unauthenticated attacker can interact directly with the system's database. This interaction can lead to unauthorized data manipulation, including viewing, creating, updating, and deleting database entries.

  • No authentication required for access.
  • Manipulate 'teamid' parameter in a specific endpoint.
  • Unauthorized database access and modification.

Live Threat

Current exploitation, exposure, and threat context

An attacker could manipulate the 'teamid' parameter in the edit-team.php endpoint to perform unauthorized actions on the system's database. This could include viewing, creating, modifying, or deleting database entries when the system is accessible via a network.

  • Database records could be affected.
  • Via a network connection to the system.
  • Unauthorized data manipulation may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Online Fire Reporting System's SQL injection vulnerability likely impacts application owners responsible for the system's codebase and database, with potential involvement from infrastructure or platform teams managing its hosting environment. The initial step is to locate all instances of the affected system, confirm their accessibility and criticality, identify the accountable business owner, and then plan remediation based on the assessed risk.

  • Identify application owners and infrastructure teams.
  • Verify system reachability and business criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the PHPGurukul Online Fire Reporting System?

This software is a web-based application designed to manage and track fire reporting data. It provides administrative tools to help organizations organize teams and oversee records within a centralized database, typically used by municipal or public-sector entities to streamline incident documentation.

How does CVE-2025-40690 work?

This is a SQL injection vulnerability, classified as CWE-89. It happens when software fails to properly sanitize user input. In this case, the application blindly trusts the 'teamid' parameter provided in a web request, allowing an attacker to inject their own database commands instead of just providing an ID number. This grants them the ability to bypass intended access controls and interact with the back-end database.

Do I need to be logged in to trigger this vulnerability?

No. The vulnerability does not require authentication or valid administrative credentials to exploit. An attacker only needs network access to the specific '/ofrs/admin/edit-team.php' endpoint. Simply navigating to the application as a guest or visitor is enough to potentially reach and manipulate the vulnerable parameter.

Why is this system considered an external risk?

Halo Surface Signal flags this as an external risk because administrative web interfaces for such systems are often deployed with internet-facing access rather than being restricted to internal networks. If your instance is reachable via the public internet, it is accessible to any remote attacker, significantly increasing the probability of unauthorized interaction.

What is the first step to address this issue?

Start by identifying every deployment of the Online Fire Reporting System within your infrastructure. Confirm which instances are accessible over the network and determine who is responsible for managing the application. Once you have an accurate inventory, assess the criticality of the data held in those databases to prioritize your risk response and plan necessary updates.

References